CVE-2025-28388: Critical severity OpenC3 COSMOS vulnerability
Published Jun 13, 2025
·Updated
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
Affected Software
2 affected components
OpenC3 COSMOS=6.0.0
OpenC3 COSMOS=6.0.0
Event History
Jun 13, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-28388?
CVE-2025-28388 is considered a high-severity vulnerability due to the presence of hardcoded credentials for the Service Account.
2
How do I fix CVE-2025-28388?
To mitigate CVE-2025-28388, you should remove the hardcoded credentials and implement a secure credential management process.
3
What versions of OpenC3 COSMOS are affected by CVE-2025-28388?
CVE-2025-28388 affects OpenC3 COSMOS version 6.0.0.
4
What risks are associated with CVE-2025-28388?
The hardcoded credentials in CVE-2025-28388 can lead to unauthorized access and potential data breaches.
5
Is there a patch available for CVE-2025-28388?
As of now, there is no specific patch available for CVE-2025-28388; users should apply best practices for credential management.